The EU's new AI rulebook is in force with fines of up to €35M — but only 18% of companies using AI have active governance, a new survey finds
Since 2 August, the transparency obligations of the European AI Act apply across the bloc, with fines of up to €35 million or 7% of worldwide turnover for prohibited practices. An IBM survey cited on 6 August shows the size of the gap: 87% of German executives do not fully understand their own AI dependencies, and "shadow AI" — employees using public AI tools without authorisation — is named as the main blind spot.
On 2 August, the AI Act's transparency obligations (clearly labelling any AI-driven interaction — chatbots, voicebots) came into application across the Union. Banks and insurers have until 2 December to bring existing systems into compliance; high-risk uses fall under a separate fine tier (€15M or 3% of turnover). Three European supervisory authorities — EBA, EIOPA and ESMA — are now pushing for stricter AI-risk governance, particularly in the financial sector.
The gap between the regulation and companies' actual readiness is stark. An IBM survey of German executives, cited on 6 August by ad-hoc-news.de, shows that 87% do not fully understand their business's dependencies on AI, and 85% admit that a week-long outage would seriously disrupt their operations. "Shadow AI" — employees using public AI tools without official sign-off — makes it worse: fewer than half of companies have an AI governance policy in place. Of the 85% of companies already using AI, only 18% have active governance measures; 40% report inaccurate AI outputs over the past year, and 27% suffered a data leak.
For AppH
- An AppH customer does not have this inventory problem in the strict sense: there is a single AI system touching their business data — the one they signed up for, declared as such in the public chat (the Art. 50 obligation is already met, verified directly in the code), never a shadow tool discovered after the fact.
- The admin kill-switch and audit log built last week (14 real AI call points, memory isolated per module) are exactly the kind of "active governance measure" the survey says is missing at 82% of companies using AI — at AppH it is not a project to build, it is already shipped.
Against / the honest limit
- AppH neither sees nor governs the OTHER AI tools an employee might use outside the product — a staff member pasting customer data into a personal ChatGPT remains a blind spot that no third-party software can close in place of a real, written internal usage policy.
- The 18% figure comes from a survey relayed by the press, not from an independent audit we could verify ourselves at the primary source — treat it as a directional order of magnitude, not a certified statistic.
The reflex would be to read this number — only 18% — as one more box to tick: "do we have active AI governance? yes/no". The more honest point is that governance cannot be decreed after the fact over a tool already deployed across the company without anyone knowing which one. At AppH the question does not arise the same way because there is a single system to govern, not a dozen tools nobody has inventoried — but that does not mean the job is done: if tomorrow your teams also use an AI outside AppManager on the same customer data, that AI stays outside our control and outside our kill-switch. What we can guarantee concerns only what happens inside AppManager — and there the rule has always been the same: no action with real consequences goes out without a human validating it first.
Reviewed by a human at AppH